Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3368 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | Blubrry PowerpressAI | 7/10/2026 | 7/10/2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services. | |
| Aplazada | Media (6.9) | — | — | WordpressAI | 6/10/2026 | 6/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data. This issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6.8.10, from 6.7 through 6.7.9, and from 6.6 through 6.6.9. | |
| Aplazada | Alta (7.2) | 0.46% | — | Publishpress CapabilitiesAI | 6/10/2026 | 6/10/2026 | Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0. | |
| Aplazada | Crítica (9.3) | 0.33% | — | Sendpress NewslettersAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. | |
| Aplazada | Media (6.5) | 0.35% | — | WordpressAI | 6/10/2026 | 6/10/2026 | Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Thimpress LearnpressAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions. | |
| Aplazada | Alta (7.2) | 0.32% | — | Blubrry PowerpressAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions. | |
| Aplazada | Alta (8.8) | 0.36% | — | Presstigers Simple Event PlannerAI | 5/10/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7. | |
| Aplazada | Media (5.1) | 0.17% | — | Thimpress LearnpressAI | 5/10/2026 | 6/10/2026 | LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that… | |
| Aplazada | Alta (7.1) | 0.10% | — | Blubrry PowerpressAI | 5/10/2026 | 6/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9. | |
| Aplazada | Media (5.3) | 0.23% | — | Blubrry PowerpressAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9. | |
| Aplazada | Alta (7.1) | 0.15% | — | Cozmoslabs TranslatepressAI | 4/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Stored XSS.This issue affects TranslatePress: from n/a through 3.3.6. | |
| Aplazada | Alta (7.2) | 0.24% | — | SeopressAI | 3/10/2026 | 6/10/2026 | The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (4.9) | 0.24% | — | SeopressAI | 3/10/2026 | 6/10/2026 | The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'seopress_google_analytics_matomo_id' parameter in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.20% | — | Wpdeveloper EmbedpressAI | 3/10/2026 | 6/10/2026 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slidesShow' Block Attribute in all versions up to, and including, 4.6.6 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (6.1) | 0.22% | — | ProfilepressAI | 3/10/2026 | 6/10/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input… | |
| Aplazada | Media (6.1) | 0.21% | — | Thimpress LearnpressAI | 3/10/2026 | 6/10/2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'orderby' parameter in all versions up to, and including, 4.4.7 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.63% | — | ProfilepressAI | 3/10/2026 | 6/10/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.15% | — | Thimpress LearnpressAI | 2/10/2026 | 2/10/2026 | Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1. | |
| Aplazada | Media (5.4) | 0.18% | — | Publishpress SeriesAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Series: from n/a through 3.1.3. | |
| Aplazada | Media (5.3) | 0.20% | — | Thimpress LearnpressAI | 2/10/2026 | 3/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnPress: from n/a through 4.4.9. | |
| Aplazada | Media (6.1) | 0.15% | — | Giveaways AND Contests BY RafflepressAI | 2/10/2026 | 2/10/2026 | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary… | |
| Aplazada | Media (5.3) | 0.20% | — | Giveaways AND Contests BY RafflepressAI | 2/10/2026 | 2/10/2026 | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public giveaway pages, allowing unauthenticated visitors to retrieve the secret key of any active giveaway that has reCAPTCHA configured. | |
| Aplazada | Crítica (9.3) | 0.24% | — | Wordpress File UploadAI | 1/10/2026 | 1/10/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | |
| Aplazada | Alta (7.5) | 0.36% | — | Thimpress LearnpressAI | 1/10/2026 | 3/10/2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback exposed on the public lp-ajax-handle (load_content_via_ajax) endpoint.… |